Security Incidents mailing list archives
5 scans of 12345 in a couple of hours. AUSCERT#36349
From: r.fulton () AUCKLAND AC NZ (Russell Fulton)
Date: Thu, 1 Jun 2000 12:48:25 +1200
Greetings, I have seen a repeat of a group of incidents that I reported to SANS, AusCERT and Securityfocus' Incident list a couple of weeks ago. Then we saw 4 scans of tcp port 12345 within a few hours, most of the scans came from ISP dialup addresses from around the world. The thing that makes these scans conspicuously related (apart from the same dst port) is that all start at address 11 in a /24 network and scan upward towards 255 -- some stop short of that though. Up to 4 syn packets are sent to each address with aprox one second between packets. The scans target different /24s in our /16 address space. Then, I theorized that 11 was a typo for 1 and no one has come up with a better suggestion. I did not receive any 'me toos' in response to my posts, are these really just targeted at us? More likely the scans are supposed to target a random class C but the programmer has failed to initialize the random number generator properly and the scans are in fact only targeting a small address space, somewhere around 130.216/16. One other detail, the source ports increment regularly suggesting that the scans are done using native stack. One response that I got suggested that this was something that was being distributed via IRC or ICQ -- this sounds plausible, it would certainly account for the strange clumping of the scans in time. It would also explain why some scans terminate prematurely -- who ever is running it gets the idea that they are running a trojan and hits ^C! This morning NZST (UTC +1200) I have seen another 5 of these scans within the last couple of hours from: bellsouth.net[209.214.106.68], pompano.net[24.26.48.126], MTY.ITESM.MX [207.249.103.172], nh.da.uu.net[63.21.109.15] and somewhere in mexico [148.246.49.124] (Arin pointed to nic.mx but i could not find any info in whois.nic.mx). So far as I can tell these scans are indistinguishable from the ones I saw two weeks ago. Cheers, Russell.
Current thread:
- AMDROCKS, (continued)
- AMDROCKS Jim Williams (May 25)
- Attacks on port 25 Vincent Lim (May 25)
- Re: Attacks on port 25 Ryan Russell (May 26)
- Re: Attacks on port 25 Bill Lavalette (May 28)
- Re: Attacks on port 25 RayW (May 29)
- AMDROCKS Jim Williams (May 25)
- invalid icmp in linux? Eric LeBlanc (May 27)
- Re: invalid icmp in linux? Jose Nazario (May 28)
- weird scan pattern Joe H (May 28)
- Re: weird scan pattern Russell Fulton (May 29)
- IDS: Scan of the week Lance Spitzner (May 30)
- 5 scans of 12345 in a couple of hours. AUSCERT#36349 Russell Fulton (May 31)
- Taiwan server compromise Claudiu Costin (May 26)
- Re: Taiwan server compromise Vortex (May 26)
- port 44767 activity Nathan Fain (May 28)
- Re: AMDROCKS Alejandro (May 26)
- Re: AMDROCKS J. S. Townsley (May 26)
- Re: AMDROCKS Lance Spitzner (May 26)
- Re: AMDROCKS Matthew F. Caldwell (May 26)
- CERT's Handbook for Computer Security Incident Response Teams (CSIRTs) Elias Levy (May 26)